Apache Thrift: Java TSaslNonblockingServer Computation.run orphans a connection on a pre-auth parse error
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: Framed transport and binary protocol size read buffers from a peer-declared length without a limit (multi-language)
Apache Thrift: Specially crafted input can crash a cglib Thrift server with invalid pointer error.
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: skip() does not apply the recursion limit (Python accelerator, PHP, Perl, Lua, Smalltalk, OCaml)
Apache Thrift: Perl FramedTransport reads and TLS socket writes re-slice the remaining buffer on every call (quadratic)
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift C++, Java, Go, netstd, Python and Delphi bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Allocation of resources without limits or throttling vulnerability in Apache Thrift ruby bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Apache Thrift: Ruby SimpleServer ends serve() on any non-Transport/Protocol exception
Apache Thrift: Perl servers end serve() when serving one connection fails
Apache Thrift: PHP framed/memory/HTTP transports re-slice the buffer on every read (quadratic)
Apache Thrift: Java TSaslNonblockingServer: residual of CVE-2026-61373 (thread-death black hole + no cross-connection budget)
Apache Thrift: Node.js TJSONProtocol uses a peer-declared container size as an unbounded loop bound
Apache Thrift: PHP TSimpleServer exits the whole process on any non-transport exception
Apache Thrift: Go THeaderTransport does not bound the inflated size of a ZLIB frame
Allocation of resources without limits or throttling vulnerability in Apache Thrift dart bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java TSaslNonblockingServer.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Apache Thrift: Integer underflow in C++ THeaderTransport allows an unauthenticated remote peer to terminate a 32-bit process
Apache Thrift: nodejs web server: no error listener on an upgraded WebSocket connection
Apache Thrift: C++ THeaderTransport::untransform() leaks the zlib stream on the error path
Apache Thrift: Python TZlibTransport stops enforcing its decompressed-size limit once the limit is exactly used up
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: Container element count not bounded by the bytes available
Apache Thrift: Node.js server.js ends the process on any per-connection error (+ two triggers)
Apache Thrift: C++ THeaderTransport::writeVarint32() stack buffer overflow on a negative protocol id
Apache Thrift: Lua THttpTransport:parseHeaders matches each header line with a backtracking pattern (quadratic)
Allocation of resources without limits or throttling, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Apache Thrift: Lua TFramedTransport/THttpTransport re-slice the buffer on every read (quadratic)
Apache Thrift: PHP thriftprotocol accelerator dereferences a missing container-element spec
Apache Thrift: cglib readall spins when the underlying read returns 0
Apache Thrift: TFramedTransport and THeaderTransport re-enter Read once per frame that carries no payload (Go)
Allocation of resources without limits or throttling, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Lua bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.